A security flaw was found in the way the File module of Drupal, the content management system, enforced download permissions on certain private files, used with certain field access modules. A remote attacker could use this deficiency to obtain private files (information disclosure) even if the were attached to fields, the attacker would not otherwise have access / ability to view. References: [1] http://drupal.org/node/1425084
This issue is scheduled to be corrected in the following drupal7 package updates: 1) drupal7-7.12-1.el6 for Fedora EPEL 6, 2) drupal7-7.12-1.el5 for Fedora EPEL 5, 3, drupal7-7.12-1.fc16 for Fedora 16, 4) drupal7-7.12-1.fc15 for Fedora 15.
This package has been released for all Fedora and EPEL branches.